Multiple Dell iDRAC Products 'IPMI' Implementation Arbitrary Command Injection Vulnerability
BID:71750
Info
Multiple Dell iDRAC Products 'IPMI' Implementation Arbitrary Command Injection Vulnerability
| Bugtraq ID: | 71750 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8272 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2014 12:00AM |
| Updated: | Dec 19 2014 12:00AM |
| Credit: | Yong Chuan Koh |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Dell iDRAC Products 'IPMI' Implementation Arbitrary Command Injection Vulnerability
Multiple Dell iDRAC Products are prone to a vulnerability that lets attackers inject arbitrary commands.
Successful exploits will allow attackers to execute arbitrary commands in the context of the affected application. This may further aid in other attacks.
Multiple Dell iDRAC Products are prone to a vulnerability that lets attackers inject arbitrary commands.
Successful exploits will allow attackers to execute arbitrary commands in the context of the affected application. This may further aid in other attacks.
Exploit / POC
Multiple Dell iDRAC Products 'IPMI' Implementation Arbitrary Command Injection Vulnerability
Attackers perform a brute-force attack to exploit this issue.
Attackers perform a brute-force attack to exploit this issue.
Solution / Fix
Multiple Dell iDRAC Products 'IPMI' Implementation Arbitrary Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.